Most organizations have an incident response plan somewhere. Far fewer have tested it. A plan is only a set of assumptions until people have tried to use it under pressure, and the middle of a real ransomware attack is a terrible time to discover that no one knows who calls the insurer or how to reach the EHR vendor on a Sunday.
A tabletop exercise is a low-cost way to find those gaps. It is a guided discussion in which your leadership team walks through a realistic scenario, step by step, and talks through what each person would do. No computers are touched and nothing is at risk. It takes about two hours and produces a list of improvements.
Include the people who would be involved in a real incident:
Administrator or executive director.
Director of nursing and a clinical leader.
Privacy and security officers, or compliance lead.
IT lead or your managed IT provider.
HR and, if relevant, finance.
Maintenance or facilities for building systems.
A communications contact for families and media, if one exists.
Optionally, a representative from your insurer, broker or legal counsel.
Small organizations can combine roles. What matters is that decision makers are in the room.
Choose a realistic situation for your organization. Three examples:
Ransomware discovered at 5 a.m. on a Saturday, with the EHR and file servers unavailable and a ransom demand displayed.
A business email compromise in which an attacker, posing as the administrator, convinces accounts payable to change a vendor's bank details, and the fraud is discovered a week later.
A lost unencrypted laptop containing resident information, taken from a staff member's car.
Write the scenario as a series of short updates, called injects, that you reveal one at a time. For example, at the start staff report they cannot log in; twenty minutes later, a ransom note appears; an hour later, a reporter calls about a rumor on social media; later, the backup system is found to be affected.
This is a learning exercise, not a test, and nobody is graded.
Answer based on what you would do today with the plan and resources you have, not what you wish you had.
Write down gaps and questions as they arise.
Appoint a facilitator who is not responsible for answering, and a note taker.
A workable agenda for two hours:
Ten minutes: introductions and rules.
Sixty to seventy-five minutes: the scenario, one inject at a time, with discussion after each.
Twenty minutes: debrief and gaps.
Ten minutes: assign actions.
Who is in charge right now?
Who needs to be told, and how, given that email may be down?
What happens to resident care? Do staff know the downtime procedures?
Who calls the insurer, legal counsel, the EHR vendor and law enforcement?
What do we tell staff, residents' families and the public?
What decisions need to be made, and who has authority to make them, for example whether to take systems offline?
What evidence should be preserved?
Is this a reportable breach under HIPAA and state law, and who decides?
Where is the plan, and could we find it without the network?
Typical gaps that exercises reveal:
Outdated contact numbers.
Nobody knows the insurer's hotline or policy requirements.
The incident plan assumes email or shared drives will be available.
Unclear authority for taking systems offline.
No printed downtime materials on one unit.
No agreement on who speaks to families.
Backups that have not been tested.
Within a week, write a brief report listing findings, owners and due dates. Update the incident response plan, revise contact lists and schedule the next exercise, ideally each year, with a different scenario. Keep records as evidence of testing for HIPAA contingency planning, CMS emergency preparedness and your cyber insurer.
You do not need special software or an expensive consultant. A conference room, a printed scenario and an honest conversation are enough to start.
UnityCare IT facilitates tabletop exercises for healthcare organizations, with scenarios tailored to long-term care and clinic operations. If you would like help planning your first one, we are glad to assist.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172